IP Library Granted Patent US 12,609,839
Granted Patent B2
US 12,609,839 · App. 18/108,032 · Granted Apr 21, 2026

Peer-to-peer updating of offline devices

Inventors: Ramanandan Nambannor Kunnath (Bangalore, IN); Rohit Pradeep Shetty (Bangalore, IN)
Assignee: Omnissa, LLC
H04L9/3268G06F8/65H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,839
App. No.
18/108,032
Granted
Apr 21, 2026
Kind
B2
Abstract

The present disclosure relates to peer-to-peer (P2P) updating of offline client devices by an online client devices. Client devices can be enrolled with a management service as managed devices. If a device lacks the ability to contact the management service, an online client device that is in communication with the offline client device can deliver updates to software, policies, or other data.

Claims (49)

1 . A system for updating an offline client device, comprising:

a processor and a memory;

machine-readable instructions stored in the memory that, when executed by the processor, cause the system to at least:

obtain device check-in data corresponding to an online client device over a network from the online client device, the device check-in data comprising device status information about the online client device, wherein the online client device is associated with a user account;

identify an offline client device associated with the user account, wherein the offline client device has failed to provide device check-in data corresponding to the offline client device for a threshold period of time;

determine, based on a device record associated with the offline client device, an update to a security policy of the offline client device;

transmit a request to communicate with the offline client device to the online client device;

generate a device payload for the offline client device, the device payload including the update to the security policy, wherein the security policy is enforced on the offline client device by a management agent executing on the offline client device;

transmit the device payload to the online client device, wherein the online client device provides the device payload to the offline client device, wherein the management agent on the offline client device receives the device payload and installs the update to the security policy on the offline client device to modify one or more security settings on the offline client device based on the update;

receive, from the online client device, the device check-in data corresponding to the offline client device, the device check-in data including a device identifier of the offline client device and device status indicating that the update to the security policy has been installed on the offline client device, wherein the offline client device transmits, to the online client device, the device check-in data corresponding to the offline client device in response to loading the device payload received from the online client device on the offline client device;

determine a compliance status of the offline client device based on the device check-in data corresponding to the offline client device received from the online client device; and

update the device record of the offline client device to reflect the compliance status, which indicates that the update to the security policy has been installed on the offline client device.

2 . The system of claim 1 , wherein the machine-readable instructions further cause the system to at least:

encrypt the device payload using a public key corresponding to the offline client device, wherein the public key further corresponds to a device certificate generated by a management service with which the online client device and the offline client device are enrolled as managed devices.

3 . The system of claim 1 , wherein the online client device and the offline client device are enrolled as managed devices with a management service.

4 . The system of claim 1 , wherein the device payload comprises a software update for installation on the offline client device.

5 . The system of claim 1 , wherein the online client device transmits the device payload to the offline client device over a peer-to-peer (P2P) communication channel, wherein the P2P communication channel is encrypted using a P2P channel certificate shared between the online client device and the offline client device.

6 . The system of claim 5 , wherein the offline client device lacks access to the network, and wherein the offline client device transmits the check-in data corresponding to the offline device to the online device using the P2P communication channel that is separate from and not part of the network.

7 . The system of claim 1 , wherein the online client device includes a first management agent enrolled with a management service under a user account and the offline client device includes a second management agent enrolled with the management service under the user account, and wherein the first management agent and the second management agent establish a Secure P2P Enrolled Device (SPED) network for delivering updates between the online client device and the offline client device.

8 . A method, comprising:

obtaining device check-in data corresponding to an online client device over a network from the online client device, the device check-in data comprising device status information about the online client device, wherein the online client device is associated with a user account;

identifying an offline client device associated with the user account, wherein the offline client device has failed to provide device check-in data corresponding to the offline client device for a threshold period of time;

determining, based on a device record associated with the offline client device, an update to a security policy of the offline client device;

transmitting a request to communicate with the offline client device to the online client device;

generating a device payload for the offline client device, the device payload including the update to the security policy, wherein the security policy is enforced on the offline client device by a management agent executing on the offline client device;

transmitting the device payload to the online client device, wherein the online client device provides the device payload to the offline client device, wherein the management agent on the offline client device receives the device payload and installs the update to the security policy on the offline client device to modify one or more security settings on the offline client device based on the update;

receiving, from the online client device, the device check-in data corresponding to the offline client device, the device check-in data including a device identifier of the offline client device and device status indicating that the update to the security policy has been installed on the offline client device, wherein the offline client device transmits, to the online client device, the device check-in data corresponding to the offline client device in response to loading the device payload received from the online client device on the offline client device;

determining a compliance status of the offline client device based on the device check-in data corresponding to the offline client device received from the online client device; and

updating the device record of the offline client device to reflect the compliance status, which indicates that the update to the security policy has been installed on the offline client device.

9 . The method of claim 8 , further comprising:

encrypting the device payload using a public key corresponding to the offline client device, wherein the public key further corresponds to a device certificate generated by a management service with which the online client device and the offline client device are enrolled as managed devices.

10 . The method of claim 8 , wherein the online client device and the offline client device are enrolled as managed devices with a management service.

11 . The method of claim 8 , wherein the device payload comprises a software update for installation on the offline client device.

12 . The method of claim 8 , wherein the offline client device lacks access to the network, and wherein the offline client device transmits the check-in data corresponding to the offline device to the online device using a peer-to-peer (P2P) communication channel that is encrypted using a P2P channel certificate shared between the online client device and the offline client device.

13 . A non-transitory computer-readable medium embodying program instructions that, when executed, cause a computing device to at least:

obtain device check-in data corresponding to an online client device over a network from the online client device, the device check-in data comprising device status information about the online client device, wherein the online client device is associated with a user account;

identify an offline client device associated with the user account, wherein the offline client device has failed to provide device check-in data corresponding to the offline client device for a threshold period of time;

determine, based on a device record associated with the offline client device, an update to a security policy of the offline client device;

transmit a request to communicate with the offline client device to the online client device;

generate a device payload for the offline client device, the device payload including the update to the security policy, wherein the security policy is enforced on the offline client device by a management agent executing on the offline client device;

transmit the device payload to the online client device, wherein the online client device provides the device payload to the offline client device, wherein the management agent on the offline client device receives the device payload and installs the update to the security policy on the offline client device to modify one or more security settings on the offline client device based on the update;

receive, from the online client device, the device check-in data corresponding to the offline client device, the device check-in data including a device identifier of the offline client device and device status indicating that the update to the security policy has been installed on the offline client device, wherein the offline client device transmits, to the online client device, the device check-in data corresponding to the offline client device in response to loading the device payload received from the online client device on the offline client device;

determine a compliance status of the offline client device based on the device check-in data corresponding to the offline client device received from the online client device; and

update the device record of the offline client device to reflect the compliance status, which indicates that the update to the security policy has been installed on the offline client device.

14 . The non-transitory computer-readable medium of claim 13 , wherein the machine-readable instructions further cause the computing device to at least:

encrypt the device payload using a public key corresponding to the offline client device, wherein the public key further corresponds to a device certificate generated by a management service with which the online client device and the offline client device are enrolled as managed devices.

15 . The non-transitory computer-readable medium of claim 13 , wherein the online client device and the offline client device are enrolled as managed devices with a management service.

16 . The non-transitory computer-readable medium of claim 13 , wherein the device payload comprises a software update for installation on the offline client device.

17 . The non-transitory computer-readable medium of claim 13 , wherein the online client device transmits the device payload to the offline client device over a peer-to-peer (P2P) communication channel, wherein the P2P communication channel is encrypted using a P2P channel certificate shared between the online client device and the offline client device.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded May 13, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067398/0613 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2023
From: NAMBANNOR KUNNATH, RAMANANDAN; SHETTY, ROHIT PRADEEP
To: VMWARE, INC.
Reel/Frame 062648/0130 →
Priority Claims (1)
IN 202241074513 · Dec 22, 2022 · national
Continuity (1)
Related Publication 20240214221A1 · Jun 27, 2024
References Cited (5)
US 20160316348A1 · Trevathan · 2016 [cited by examiner]
US 20170048097A1 · Kavatage · 2017 [cited by examiner]
US 20210014921A1 · Cleaver · 2021 [cited by examiner]
US 20210211418A1 · Nambannor Kunnath · 2021 [cited by examiner]
US 20220377550A1 · Mataic · 2022 [cited by examiner]